hacker-news · Crawled Sep 22, 2026

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

5 IoCs
Read original article ↗

AI Summary

A malicious npm package named 'tw-pkgprobe-7731' was uploaded to the npm registry by a now-defunct account 'twdepprobe7731', masquerading as an authorized Twilio bug-bounty probe. The package targets Twilio developers by checking for specific environment conditions and, if met, exfiltrates environment variables, system configurations, and Twilio credentials such as ACCOUNT_SID and AUTH_TOKEN. Later versions attempted to inject malicious npm packages and perform OSINT gathering on Twilio-related infrastructure, though the final versions reverted to benign behavior, suggesting possible testing or evasion. The package violates Twilio's HackerOne security research guidelines and shows no obfuscation, indicating a low sophistication threat actor.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Package tw-pkgprobe-7731 Details →
Registry User twdepprobe7731 Details →
Domain support-api[.]us1[.]twilio[.]com Details →
Domain kafka-ui[.]au1[.]twilio[.]com Details →
Domain litellm[.]ai-services[.]corp[.]twilio[.]com Details →